IBM GINA for NT Privilege Escalation Vulnerability
BID:608
Info
IBM GINA for NT Privilege Escalation Vulnerability
| Bugtraq ID: | 608 |
| Class: | Unknown |
| CVE: |
CVE-1999-0718 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | The vulnerability was posted to NTBugtraq on August 23. Vulnerability originally identified by Frank Pikelner <[email protected]>. |
| Vulnerable: |
IBM GINA for NT 1.0 |
| Not Vulnerable: | |
Discussion
IBM GINA for NT Privilege Escalation Vulnerability
IBM has written a replacement GINA for Windows NT to allow NT hosts to authenticate against OS/2 domains. On machines running the modified GINA, the creation of a specific Registry key under HKLM\System\CurrentControlSet\Services\IBMNeTNT may allow a user to add any Group to the "Local Administrators" group upon next reboot. ACL permissions over this key allow non-administrators to create the necessary key and value.
IBM has written a replacement GINA for Windows NT to allow NT hosts to authenticate against OS/2 domains. On machines running the modified GINA, the creation of a specific Registry key under HKLM\System\CurrentControlSet\Services\IBMNeTNT may allow a user to add any Group to the "Local Administrators" group upon next reboot. ACL permissions over this key allow non-administrators to create the necessary key and value.
Solution / Fix
IBM GINA for NT Privilege Escalation Vulnerability
Solution:
Modify the ACLs over the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IBMNeTNT\GroupMapping key to:
System: Full
Administrators: Full
Everyone: Read
Solution:
Modify the ACLs over the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IBMNeTNT\GroupMapping key to:
System: Full
Administrators: Full
Everyone: Read